CRL Certificate Status Checker
Description
Certificate status checker using a CRL (certificate revocation list) to check the status of certificates.
Periodically updates the CRL using the configured "CRL Fetcher". The latest fetched CRL is cached in memory and if configured, persisted into a file cache.
The CRL Distribution Point Extension of the certificate is not taken into account. Use plugin "CRL Distribution Point Extension CRL Checker" to consider the CRL Distribution Point Extension of the certificate being checked.
May be used by
OAuth 2.0 Client mTLS Authentication Caching Certificate Status Checker STET PSD2 Authenticator NextGenPSD2 Certificate Authenticator Certificate Authenticator Certificate Authenticator CRL Distribution Point Extension CRL Checker Certificate Token Authenticator HTTP Signature Verification Credential Extractor Client Certificate (X.509) Request Authentication
Properties
CRL Fetcher (
crlFetcher) Description
The plug-in used to periodically obtain the CRL.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Fetch Interval Seconds (
fetchIntervalSeconds) Description
The number of seconds between two attempts to fetch the current CRL. This plug-in uses always the latest fetched CRL. Values lower than one minute (60) are not allowed.
If the CRL cannot be fetched, a warning is logged and the plug-in tries again after the waiting some time specified by property
If the CRL cannot be fetched, a warning is logged and the plug-in tries again after the waiting some time specified by property
retry-interval-seconds. Attributes
Long
Mandatory
Retry Interval Seconds (
retryIntervalSeconds) Description
If a CRL cannot be fetched (because the CRL fetcher plug-in throws an exception), this plug-in retries after waiting a certain time. This property specifies the amount of seconds to wait before retrying. The minimum allowed value is 10 seconds.
Attributes
Long
Mandatory
Retry Count (
retryCount) Description
If a CRL cannot be fetched (because the CRL fetcher plug-in throws an exception), this plug-in retries after waiting a certain time specified by property
The number of retries times the amount of time to wait between retries must not be greater than the fetch interval.
retry-interval-seconds. This property specifies the maximum number of retries before the plug-in gives up. After giving up, the plug-in will try again after the normal fetch interval (specified by property fetch-interval-seconds has been passed.
The number of retries times the amount of time to wait between retries must not be greater than the fetch interval.
Attributes
Integer
Mandatory
CRL Validity Seconds (
crlValiditySeconds) Description
The number of seconds a CRL is considered valid. The validity is counted from the update time of the CRL (this is an attribute of the CRL itself and does not depend on the time it was fetched).
Make sure that the validity period is considerably larger than the fetch interval.
The minimum value is one minute (60).
Make sure that the validity period is considerably larger than the fetch interval.
The minimum value is one minute (60).
Attributes
Long
Mandatory
Fail Silently If CRL Expired (
failSilentlyIfCrlExpired) Description
Optional property specifying how this class certificate status checker should behave if the latest available CRL has expired:
If set to
If set to
If set to
TRUE, calling method isRevoked(X509Certificate) always returns true and a warning is logged.
If set to
FALSE (the default), calling method isRevoked(X509Certificate) will result in a CertificateStatusCheckerException. Attributes
Boolean
Optional
Default value
false
Cache File (
cacheFile) Description
Specifies a readable and writable file used by the plug-in to cache the latest fetched CRL. This is valuable in the case of a server restart at a time when there is a valid CRL from the last successful fetch but no CRL can be fetched at startup. In this case, the locally cached file is used.
This property is optional. If not defined, no local file cache will be used.
Caution:Make sure the file is readable and writable. Be careful with relative paths and permissions.
This property is optional. If not defined, no local file cache will be used.
Caution:Make sure the file is readable and writable. Be careful with relative paths and permissions.
Attributes
File/Path
Optional
Included Issuer (
includedIssuer) Description
Specifies that only certificates with a issuer matching against this pattern are checked against the CRL. Certificates that do not match this pattern are ignored and true is returned upon the check.
Attributes
RegEx
Optional
Keystore Config (
keystoreConfig) Description
The keystore containing the CA certificate to verify the signature of the CRL.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)
type: CrlCertificateStatusChecker
id: CrlCertificateStatusChecker-xxxxxx
displayName:
comment:
properties:
cacheFile:
crlFetcher:
crlValiditySeconds:
failSilentlyIfCrlExpired: false
fetchIntervalSeconds:
includedIssuer:
keystoreConfig:
retryCount:
retryIntervalSeconds: